Zolteria Privacy Notice

|

Last Updated – 29 April 2026 

1. Overview  

Zolteria (“we, us, our”) is a data protection compliance platform where data sharing is reimagined. Zolteria is designed to provide a variety of tools that organisations can use to make data protection compliance seamless by streamlining creation, management and approval of information sharing agreements and beyond, including (but not limited to) Data Sharing Agreements, Data Processing Agreements, Data Sharing Frameworks and Data Sharing Specifications. The platform includes a secure, centralised environment with a full library of pre-approved, ready-to-use, and customisable templates, allowing organisations to manage and monitor all agreements seamlessly. Members of the public can also use Zolteria to exercise their data subject rights and manage their data sharing preferences by submitting their requests to relevant organisations, as well as record their interest to be contacted in the future to participate in research projects conducted by partner organisations. 

Zolteria is wholly owned by Information Governance Services Ltd (“IGS”), which is incorporated in England and Wales with the company number 11779744 and whose registered address is Furlong House, 10A Chandos Street, London, United Kingdom, W1G 9DQ.  

This Privacy Notice explains what information we will be collecting about you and why, how that information will be used, how we keep it safe, and what your rights are around the data we collect and use. 

This Privacy Notice covers any personal data we process when you have:  

  • set up an account on Zolteria to make use of our services; or 

  • interacted with our website and have consented to the use of our cookies. 

Personal data is information relating to identified or identifiable person which means information we collect about you which can be used to draw conclusions about your identity. 

We take our responsibilities under the UK General Data Protection Regulation (UK GDPR), Data (Use and Access) Act 2025, Data Protection Act 2018 and Privacy and Electronic Communications Regulations 2003 as amended by European Directive 2009/136/EC (collectively referred to as “data protection laws”) very seriously. You can be assured that your information will always be used appropriately, lawfully and in line with the applicable data protection laws. We will store your data securely with appropriate safeguards in place to protect it against unauthorised or unlawful processing and ensure that we do not store any of your data for longer than it is strictly necessary to do so.  

In most instances, due to the nature of our services, we act as a “data controller”, that is, we collect personal data for our own purposes. A data controller under the UK GDPR is the entity or natural person determining the purposes and means of the processing. In other words, we decide why and how the personal data is used. For example, we act as a data controller in relation to the data that you submit to us when creating an account on Zolteria.  

However, there are limited instances where we may act as a “data processor”, where we handle personal data on behalf of other entities acting as data controllers. Where we act as a data processor, we only use personal data in line with the instructions that we receive from the data controller. For example, we act as a data processor where our partner organisations contact you about recruitment into a research project that they are sponsoring, if you have agreed to be contacted. Under the UK GDPR, the data controllers are required to inform you about their activities concerning your personal information. Therefore, where relevant we will refer you to their website and privacy policy.  

2. What personal data do we collect, why do we collect it?

Zolteria uses personal data only where it is strictly necessary to do so for our purposes. When you create an account on Zolteria as an Organisation Member (e.g. Admin, User, Data Protection Professional, Healthcare Specialist, Researcher), we may collect the following information:  

Data Purpose(s) Lawful basis under UK GDPR
User information:
  • First and last names
  • Job title
  • Email address

To create and manage user accounts.

To enable authentication, secure signing and collaboration.

To provide customer support and notifications.

Article 6(1)(b): Performance of a contract
Profile picture (optional) To enhance customer experience and collaboration. Article 6(1)(a): Consent
User session and activity information

To enable navigation in the platform after login.

To improve platform and enhance user experience.

Article 6(1)(b): Performance of a contract

Article 6(1)(f): Legitimate interests

Payment details (including card or bank information for transfers and direct debits) To enable subscriptions and purchases. Article 6(1)(b): Performance of a contract
Purchase and subscription history

To provide customer support and notifications.

To improve and protect the platform.

Article 6(1)(b): Performance of a contract

Article 6(1)(f): Legitimate interests

Some personal data are sensitive and are, therefore, classified as ‘special category of personal data’ under the UK GDPR. Because of their sensitive nature, special categories of personal data are treated differently under the UK GDPR and Article 9 of the UK GDPR prohibits processing of special category data unless one of the conditions for processing is satisfied. We may occasionally collect personal data which falls under this category. When we do this, we will rely on one of the exceptions and conditions under Article 9 of the UK GDPR as set out in the table below.  

If you create an account on Zolteria as a Public Member for the purposes of managing your data subject rights and data sharing preferences, we may collect the following information:  

Data Purpose(s) Lawful basis under UK GDPR
User information:
  • First and last names
  • Email address
  • Phone number
  • Home address (address line, city, postcode)
  • Date of Birth
  • Gender (optional)

To create and manage user accounts.

To enable authentication, secure signing and collaboration.

To provide customer support and notifications.

Article 6(1)(a): Consent

Article 6(1)(b): Performance of a contract

Ethnicity (optional)

To create and manage user accounts, to enable authentication, secure signing and collaboration.

This data category is optional, meaning users are not required to disclose this information to create an account.

Article 6(1)(a): Consent

Article 9(2)(a): Explicit consent

Profile picture (optional) To enhance customer experience and collaboration. Article 6(1)(a): Consent
User ID for identity verification:
  • Verified First and last name
  • Verified address
  • Document type
  • Issuing country
  • Issued date
  • Document/selfie errors
User verification will be required to enable users to raise data subject requests to other organisations. Article 6(1)(b): Performance of a contract
User session and activity information

To enable navigation in the platform after login.

To improve platform and enhance user experience.

Article 6(1)(b): Performance of a contract

Article 6(1)(f): Legitimate interests

Research options:
  • Research groups
  • Research consent timestamp
  • Form responses

Applicable only to users relying on Zolteria to allow partner organisations to contact them about scientific research opportunities.

Data collected to enable the functionality.

Article 6(1)(a): Consent

Article 6(1)(b): Performance of a contract

Recorded data subject requests and data sharing preferences:
  • Request history
  • Notes
  • Decision timestamps

Applicable only to users relying on Zolteria to communicate their data sharing preferences and to manage data requests to organisations.

Data collected to enable the functionality.

Article 6(1)(a): Consent

Article 6(1)(b): Performance of a contract

Health data (inferred)

Applicable only to users consenting to become part of Zolteria's “consent to contact” registry to allow partner organisations to contact them about research opportunities.

Health data is not collected directly by Zolteria but depending on the type of research that you demonstrate interest, certain health information may be inferred from your choice, and such health information may count as special category data.

Article 6(1)(a): Consent

Article 9(2)(a): Explicit consent

For marketing purposes, such as marketing communications and forms, we may collect the following information: 

We intend to rely on our legitimate interests to process some categories of your personal data. Our interests are in accordance with data protection laws as it is legitimate for us to maintain our services to the highest possible standards, and they are not overridden by your fundamental rights and freedoms. 

Our legitimate interests are: 

  • Providing and improving our platform: Our aim is to deliver secure, reliable and efficient services to our users. To that end, we will capture some personal data to improve platform functionality, security and user experience.  

  • Marketing and communications: we may process your personal data for our marketing and communications purposes. This will happen where we have relevant updates or information about platform features, services or changes to existing partner organisations. For more information about our use of data for marketing, including the possibility of withdrawing from receiving communications, please see section 3 of this Privacy Notice. 

3. How do we use your data for marketing including direct marketing?    

We may process your data for marketing purposes. Marketing communications that you receive from us may include but it is not limited to offer about our products and services, primarily via email. 

For these communications, we use your personal data as described in section 2 above. We rely on your consent or our legitimate interests to process your personal data to send you these communications. 

You will always have the option to withdraw/opt-out from receiving marketing communications from us. To do so, you can reach out to us at: info@informationgovernanceservices.com. You can also unsubscribe from email marketing preferences by clicking on unsubscribe link in email. 

Besides direct marketing communications, some of the data we collect via cookies when you browse our website may be used for marketing and analytics purposes. Please see our Cookie Policy on [INSERT LINK] for more details on the cookies we use and your related rights.  

4. Do we collect or use personal information about children? 

We do not provide services targeted at children and therefore, do not collect or use personal information about children.  

5. How long do we keep your data?  

We only keep your personal data for as long as it is needed to meet the purposes we specified above. Once your personal data is no longer needed, we securely anonymise and/or delete your personal data. Anonymising your data means that we apply a process to your data that prevents us from identifying you from that information.   

If we rely on your consent to process your personal data, we will only store your data for as long as you consent to us holding it. 

Overall, when determining the relevant retention periods for personal data, we will take the following factors into account:   

  • The purposes for which the personal data are being processed;  

  • Whether we have consent from you to store your personal data;  

  • Legal or regulatory requirements;  

  • Statute of limitations under applicable laws;  

  • Legal claims or potential disputes;  

  • Requests to have the personal data deleted; and  

  • Guidelines issued by the relevant data protection authorities and industry standards.

6. With whom do we share your personal data?

We work with third parties with whom we have a contractual relationship to help us process your data for the proper functioning of the platform and fulfil the purposes specified above. Where information is shared, it will be done on strictly need-to-know basis and limited to what is necessary. As such, all personal data will only be shared in order to facilitate or assist with our contractual, legal obligations or identified legitimate interest.  

A list of our current service providers with whom your data may be shared, and the functions they undertake can be found below: 

Data Purpose(s) Lawful basis under UK GDPR
Contact information:
  • First and last name
  • Email address
  • Phone number
  • Job title
For the purposes of sending offers and communications about our products and services.

Article 6(1)(a): Consent

Article 6(1)(f): Legitimate interests

Organisation Name Purposes Location of Data Processing
ClerkAuthentication and authorisation of usersUnited States (Adequacy decision as per UK Extension to EU-US Data Privacy Framework)
CloudflareDNS Management and cyber securityUnited States (Adequacy decision as per UK Extension to EU-US Data Privacy Framework)
GoogleStorage for uploaded files and social loginRepublic of Ireland (EU)
Microsoft LimitedEmail delivery and social loginUnited Kingdom
Neon (PostgreSQL)Storage of all application dataUnited States (Adequacy decision as per UK Extension to EU-US Data Privacy Framework)
SendGridTransactional email deliveryUnited States (Adequacy decision as per UK Extension to EU-US Data Privacy Framework and Binding Corporate Rules for in-group transfers)
StripeOnline payment processing platform and ID verification platformUnited States (Adequacy decision as per UK Extension to EU-US Data Privacy Framework)
TwilioSMS delivery for research invitationsUnited States (Adequacy decision as per UK Extension to EU-US Data Privacy Framework and Binding Corporate Rules for in-group transfers)
VercelApplication hostingUnited States (Adequacy decision as per UK Extension to EU-US Data Privacy Framework)

We are very careful when we choose these service providers and only transfer your data outside of the UK where we have a lawful way to do so. We take all reasonable steps to confirm that an equivalent level of data protection is ensured. 

When we disclose your personal data to these service providers, they may only process your personal data under our instructions and to perform the tasks we require. 

Additionally, we may disclose your personal data in connection with court orders, legal proceedings, government inquiries or law enforcement authorities. If we do share, for these purposes, we will rely on UK GDPR Article 6(1)(c) – legal obligation and do so in compliance with Schedule 1 of the Data Protection Act 2018. 

7. How do we keep your information confidential and safe?  

We take the security of your personal data very seriously. We ensure that it is protected with multiple levels of security, including 256-bit AES encryption at rest which is widely considered to be one of the most secure methods of protecting data, and access controls. Access controls ensure that only a limited number of people have access to your data. 

We ensure that all personal data is backed up, and we have a business continuity plan in place. In the event of an unexpected disruption to our service and business operation, we will be able to restore availability.  

We store your data in data centres that are accredited to international and industry specific compliance standards such as ISO 27001:2022, SOC 2 Type I and Type II and SOC 3 certifications.  

8. Your data subject rights

As a data subject, you have various rights about how your personal data is used. 

Individual Right Information about your rights
The right to object

In certain circumstances, as a data subject, you have the right to object to the processing of your data. Where we are using your data to carry out any direct marketing you have the absolute right to object to the processing of your personal data. The method of objection to such processing will appear in the subject of the direct marketing in question.

Please note that where the processing in question is not for direct marketing purposes, your right to object is not absolute. This means that we need to perform a balancing exercise comparing your interests with ours. We can refuse to comply with your request if we have overriding compelling legitimate grounds for the processing. If that is the case, we will inform you as soon as we can and let you know about our compelling legitimate grounds.

You also have the right to object to the processing of your data where a data controller processes personal data on for purpose of a public task or under legitimate interests. Please note that we do not carry out any data processing under either of these lawful mechanisms, as such, the right to object in these specific circumstances do not apply.

The right to withdraw consent

Where we process personal data based on your consent, as detailed in section 2 of this Privacy Notice, you have the right to withdraw your consent. At this moment, we will stop processing the data that was conditional to your consent.

Please note that the withdrawal of consent shall not affect the processing of data that was carried out before the withdrawal.

The right to be informed

As a data subject, you have the right to be informed about how your data is collected and used. This Privacy Notice serves as our transparency material for data subjects as to how your personal data is used, informing you of our uses.

This Privacy notice aims to provide you with information in a concise, transparent, intelligible way which is easily accessible and uses a clear and plain language.

The right of access

As a data subject, you have the right to access and receive a copy of the personal data we hold on you. You can make a subject access request to us for this information.

We will provide the information in an accessible, concise and intelligible format, and it will be disclosed in a secure way.

We have processes to ensure that you will receive it without undue delay and within one month of receipt, with the exception of circumstances in which we can lawfully extend the time limit to respond to your request.

We have the right to refuse such a request where there is a relevant restriction, or where the request is manifestly unfounded or excessive.

The right of rectification

As a data subject, you have the right to rectify inaccurate personal data which we hold on you. You can make a request to us verbally or in writing if you believe that information we hold on you is inaccurate. To update or edit your personal data held by us, including your communication preferences, please contact us using the contact details set out under “Making a complaint”.

We have the right to refuse a request, and we are aware of the information we need to provide to you.

We have processes to ensure the response to a request for rectification without undue delay and within one month of receipt. In certain circumstances, we can extend the time limit to respond to a request.

The right of erasure In certain circumstances, as a data subject, you have the right to request verbally or in writing that we erase the personal data we hold about you. You can only request the personal data is erased where: it is no longer necessary for the purposes we collected it, if you provided the information by consent and you withdraw your consent, we have processed the information unlawfully, the erasure is in line with a legal obligation.
The right of restricting processing In certain circumstances, as a data subject you have the right to request verbally or in writing that we restrict the processing of your data for a period of time. You can only request the processing of personal data is restricted where: you are contesting the accuracy of the personal data and it is being verified, the data has been unlawfully processed, we no longer need the personal data but you require us to keep it in order to establish, exercise or defend a claim.
The right of data portability

As a data subject, you have the right of data portability, meaning you have the right to receive a copy of your personal data in a structured, commonly used and machine-readable format.

The right of portability only applies where we have collected this information via consent or the performance of a contract (see lawful bases above) and we are processing the data by automated means (i.e. not paper files).

Rights related to automated decision-making including profiling We do not make any automated decisions or automated profiling about any data subjects.

You can find out more about your rights by visiting the Information Commissioner’s Office’s website in this link

9. How can you exercise your rights?  

If you want to make use of your rights where we are the data controller, you can exercise your rights by using our contact details displayed within section 15 of this Privacy Notice (“How can you contact us?”).

10. What is the timeframe for receiving a response?  

We will always aim to respond to your request as soon as we can, and always within one month upon receipt of the request.   

In certain circumstances, we are entitled to extend this period by another two months. This will be the case where your request is complex. We will notify you about this extension as soon as we can. 

11. Verifying your identity 

In order to comply with your request, we will need to verify your identity. This will be done so that we do not accidentally disclose your personal information to an unauthorised person. To that end, we may ask for confirmation of your identity as part of the process which may include requesting further documentation and processing of personal information where we have reasonable doubts about your identity.  

12. When can we refuse to comply with your requests or charge a fee?  

Usually, we will comply with your requests without undue delay and free of charge. However, there are certain circumstances where we are legally allowed to refuse to comply or charge a reasonable fee. This will be the case where your request is manifestly unfounded or excessive. If we decide to refuse to comply or charge you a reasonable fee, we will inform you about our decision. 

Furthermore, your right to object might be further restricted if the processing is occurring for historical or scientific research purposes. You can read more about this restriction on the ICO’s website

13. Do we make decisions based solely on automated processing?  

We do not make decisions based on automated processing without human involvement. 

14. Making a complaint 

Should you have any queries about the how your information is used, or wish to make a complaint about how your data has been used, then please contact our team at: info@informationgovernanceservices.com

If you are unhappy with the way we use your information or about our response to your request, you have the option of contacting the Information Commissioner’s Office (ICO), who is the UK’s independent data protection supervisory authority. The ICO has multiple ways of which they can be contacted, including telephone and live chat. More information about how you can get in contact with the ICO can be found below:  

Address:

Information Commissioner’s Office 

Wycliffe House 

Water Lane 

Wilmslow 

Cheshire  

SK9 5AF 

Telephone number: 0303 123 1113 (local rate) 

Online: you can make a complaint or raise a concern via the ICO’s website

15. How can you contact us?  

If you would like to contact us in respect of any element of this Privacy Notice, or where you wish to raise a complaint or grievance, you can do so using the contact details provided below:  

Address:

Furlong House 

10A Chandos Street 

London 

W1G 9DQ 

United Kingdom 

Phone Number: 0208 106 7936 

E-mail:info@informationgovernanceservices.com

16. Changes to this Notice 

We may update this Notice from time to time. If we make any material changes to this Notice, we will change the “last updated” date of the Notice and notify you by your chosen form of communication, where applicable and appropriate. Changes to this Notice are effective when they are posted on this page.